CVE-2026-107270: Gophish
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.
Affected products
- Gophish Gophish: up to and including 0.12.1
Published 2026-10-07. Last modified 2026-10-07.